Writing Security Tools and Exploits
Writing Security Tools and Exploits
Editorial Reviews
Book Description
Learn to Write the Security Tools the Other Books Only Teach You to Use
Exploits. In information technology circles, the term exploits has become synonymous with vulnerabilities. It is a scary word that can keep you up at night wondering if you have purchased the best firewalls, configured your new host-based intrusion prevention system correctly, and patched your entire environment. It's also a topic that can enter the security water-cooler discussions faster than McAfee's new wicked antivirus software or Symantec's latest acquisition. Exploits are proof that the computer science or software programming community still does not have an understanding of how to design, create, and implement secure code.
Write Solid Shellcode
Learn the techniques used to make the most out of vulnerabilities by employing the correct shellcode. Reverse Connection Shellcode
See how reverse connection shellcode makes a connection from a hacked system to a different system where it can be caught using network tools such as netcat. Buffer Overflow Exploits
Find techniques to protect against buffer overflows such as allocating buffers for string operations dynamically on the heap. Heap Overflows
Heap overflows have become the most prominent software security bugs. See how they can have varying exploitation techniques and consequences. Format Strings
Format string vulnerabilities occur when programmers pass externally supplied data to a print f function (or similar) as part of the format string argument. Race Conditions
Nearly all race condition exploits are written from a local attacker's perspective and have the potential to escalate privileges, overwrite files, or compromise protected data. Exploitable Integer Bugs
See how integer bugs are harder for a researcher to spot than stack overflow vulnerabilities and learn why the implications of integer calculation errors are less understood by developers as a whole. Code for Nessus
Use NASLs to check for security vulnerabilities or misconfigurations. Metasploit Framework (MSF)
Use MSF and its components, msfweb, msfconsole, and msfcli, as an exploitation platform. Meterpreter Extensions
Use the power of the Meterpreter payload system to load custom-written DLLs into an exploited process's address space.
Writing Security Tools and Exploits,James C. Foster,Syngress Publishing,1597499978,Computer Books: General,Computer Data Security,Computers,Computers - Computer Security,Programming - Software Development,Security - General,Computers / Computer Security,Computers / Security,Computers/Programming - Software Development,Reverse Engineering, 0-day, Shellcoding, Porting Code, Security COM Objects, Writing Portable Code, NASL, Sockets, WinSock, Exploits, Syscalls, Coding, Programming, Vulnerabilities, hacking, hackers, Buffer overflows, vulnerability, exploit, stack, Registers, variables, heap, payload, Attack vector, Trapping attacks, Non-executable stacks, Snort, Nessus, Ethereal, open source, rules, plugins, captures, NASL, Nessus Attack Scripting Language, intrusion detection system, IDS, packet sniffer, packet sniffing, network scanning, network assessment, network auditing, packets, vulnerability, exploit, hacking, capture filters, display filters, nikto, HTTP, FTP, brute force, Trojan horse, false positives, vulnerability fingerprinting, knowledge base, Ethernet, TCP/IP, protocols, Tethereal, Editcap, Mergecap, WinCap, libcap, binary, source code, MAC addresses, bitwise operators, Boolean, byte, TCP scan, SYN scan, Xmas scan, Null scan, PCAP, OSI model, preprocessors, portscan, SNMP, ICMP, frag2, barnyard, ACID
English Books:
- XDoclet in Action (In Action series)
- XForms: XML Powered Web Forms
- XML and Perl
- XML by Example (2nd Edition)
- XML Data Management: Native XML and XML-Enabled Database Systems
- XML for Web Designers Using Macromedia Studio MX 2004 (Internet Series)
- XML in 60 Minutes a Day
- XML in Flash
- XML Internationalization and Localization
- XML Pocket Reference
English Books
Recommended Books
- Art-Sites San Francisco: The Indispensable Guide to Contemporary Art-Architecture-Design
- Winter House
- The Art of The Two Towers
- Supply Chain Management with APO : Structures, Modelling Approaches and Implementation of mySAP SCM
- The Conditions of Learning : Training Applications
- Soil Erosion, Conservation, and Rehabilitation
- Principles and Techniques for an Integrated Chemistry Laboratory
- Strong Solids
- The Maintenance Man : A Novel
- The Folk Remedy Encyclopedia : Olive Oil, Vinegar, Honey and 1,001 Other Home Remedies
- The Dog's Bark: Simple Truths from a Wise Pet
- The British Country House in the Eighteenth Century
- The Second World War
- Serious Adverse Events : An Uncensored History of AIDS
- The Essential Swimmer